bootcamp

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The run.sh script is vulnerable to command injection through its session resumption logic. The cmd_resume function reads the role value from the local state file (~/.embry/bootcamp_state.json) using grep and sed without performing any validation on the extracted string. This value is then passed to the save_state function, which interpolates it into an unquoted heredoc (cat > ... <<EOJSON). If the state file is modified (e.g., by another process or manual edit) to contain a command substitution payload such as "role": "$(id)", the command will be executed by the shell when save_state is called during the resumption process.
  • [SAFE]: The start command implementation correctly validates the --role argument against a strict whitelist ('operator', 'compliance-officer', 'developer') before processing, preventing direct injection via initial command-line arguments.
  • [SAFE]: The skill follows secure patterns for cross-skill execution by deriving the SKILLS_DIR path relative to the script's own directory and explicitly unsetting VIRTUAL_ENV to avoid environment conflicts during subprocess calls.
  • [SAFE]: No external network dependencies or remote code downloads were detected; all operations are performed using local shell scripts and internal system tools.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — bootcamp